Sample viewer

vx.netlux.org/Virus.DOS.Armen.509

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:19:47.114639347Z 65 PC: 12a52 | Delete file (Filename = 'is started by using +the SHELL command in the CONFIG.SYS file. F##¸#ã#,$z$À$%U% %à%,&y&')
2018-12-17T22:19:47.121276992Z 42 PC: 9fb8c | Get date 0x9fb8c: cmp al, 5
0x9fb8e: jne 0x9fbbf
0x9fb90: mov ah, 9
0x9fb92: mov dx, 0x1ea
0x9fb95: push cs
0x9fb96: pop ds
0x9fb97: pushf
0x9fb98: lcall ptr cs:[0x1fd]
0x9fb9d: mov bx, 0xb800
0x9fba0: mov es, bx
0x9fba2: mov cx, 0x230
0x9fba5: mov bx, 0
0x9fba8: mov word ptr es:[bx], 0x4420
0x9fbad: mov word ptr es:[bx + 0x460], 0x1120
0x9fbb4: mov word ptr es:[bx + 0x8c0], 0x6620
0x9fbbb: inc bx
0x9fbbc: inc bx
0x9fbbd: loop 0x9fba8
0x9fbbf: pop ds
0x9fbc0: pop es
2018-12-17T22:19:47.123930408Z 77 PC: 11fe0 | Get program return code
2018-12-17T22:19:47.125270973Z 42 PC: 9fb8c | Get date 0x9fb8c: cmp al, 5
0x9fb8e: jne 0x9fbbf
0x9fb90: mov ah, 9
0x9fb92: mov dx, 0x1ea
0x9fb95: push cs
0x9fb96: pop ds
0x9fb97: pushf
0x9fb98: lcall ptr cs:[0x1fd]
0x9fb9d: mov bx, 0xb800
0x9fba0: mov es, bx
0x9fba2: mov cx, 0x230
0x9fba5: mov bx, 0
0x9fba8: mov word ptr es:[bx], 0x4420
0x9fbad: mov word ptr es:[bx + 0x460], 0x1120
0x9fbb4: mov word ptr es:[bx + 0x8c0], 0x6620
0x9fbbb: inc bx
0x9fbbc: inc bx
0x9fbbd: loop 0x9fba8
0x9fbbf: pop ds
0x9fbc0: pop es
2018-12-17T22:19:47.127613087Z 72 PC: 12174 | Allocate memory
2018-12-17T22:19:47.130056822Z 42 PC: 9fb8c | Get date 0x9fb8c: cmp al, 5
0x9fb8e: jne 0x9fbbf
0x9fb90: mov ah, 9
0x9fb92: mov dx, 0x1ea
0x9fb95: push cs
0x9fb96: pop ds
0x9fb97: pushf
0x9fb98: lcall ptr cs:[0x1fd]
0x9fb9d: mov bx, 0xb800
0x9fba0: mov es, bx
0x9fba2: mov cx, 0x230
0x9fba5: mov bx, 0
0x9fba8: mov word ptr es:[bx], 0x4420
0x9fbad: mov word ptr es:[bx + 0x460], 0x1120
0x9fbb4: mov word ptr es:[bx + 0x8c0], 0x6620
0x9fbbb: inc bx
0x9fbbc: inc bx
0x9fbbd: loop 0x9fba8
0x9fbbf: pop ds
0x9fbc0: pop es
2018-12-17T22:19:47.132462301Z 72 PC: 1218d | Allocate memory
2018-12-17T22:19:47.135169774Z 42 PC: 9fb8c | Get date 0x9fb8c: cmp al, 5
0x9fb8e: jne 0x9fbbf
0x9fb90: mov ah, 9
0x9fb92: mov dx, 0x1ea
0x9fb95: push cs
0x9fb96: pop ds
0x9fb97: pushf
0x9fb98: lcall ptr cs:[0x1fd]
0x9fb9d: mov bx, 0xb800
0x9fba0: mov es, bx
0x9fba2: mov cx, 0x230
0x9fba5: mov bx, 0
0x9fba8: mov word ptr es:[bx], 0x4420
0x9fbad: mov word ptr es:[bx + 0x460], 0x1120
0x9fbb4: mov word ptr es:[bx + 0x8c0], 0x6620
0x9fbbb: inc bx
0x9fbbc: inc bx
0x9fbbd: loop 0x9fba8
0x9fbbf: pop ds
0x9fbc0: pop es
2018-12-17T22:19:47.138106696Z 37 PC: 123c4 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:19:47.139484804Z 42 PC: 9fb8c | Get date 0x9fb8c: cmp al, 5
0x9fb8e: jne 0x9fbbf
0x9fb90: mov ah, 9
0x9fb92: mov dx, 0x1ea
0x9fb95: push cs
0x9fb96: pop ds
0x9fb97: pushf
0x9fb98: lcall ptr cs:[0x1fd]
0x9fb9d: mov bx, 0xb800
0x9fba0: mov es, bx
0x9fba2: mov cx, 0x230
0x9fba5: mov bx, 0
0x9fba8: mov word ptr es:[bx], 0x4420
0x9fbad: mov word ptr es:[bx + 0x460], 0x1120
0x9fbb4: mov word ptr es:[bx + 0x8c0], 0x6620
0x9fbbb: inc bx
0x9fbbc: inc bx
0x9fbbd: loop 0x9fba8
0x9fbbf: pop ds
0x9fbc0: pop es
2018-12-17T22:19:47.141832596Z 37 PC: 123cb | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:19:47.143949314Z 42 PC: 9fb8c | Get date 0x9fb8c: cmp al, 5
0x9fb8e: jne 0x9fbbf
0x9fb90: mov ah, 9
0x9fb92: mov dx, 0x1ea
0x9fb95: push cs
0x9fb96: pop ds
0x9fb97: pushf
0x9fb98: lcall ptr cs:[0x1fd]
0x9fb9d: mov bx, 0xb800
0x9fba0: mov es, bx
0x9fba2: mov cx, 0x230
0x9fba5: mov bx, 0
0x9fba8: mov word ptr es:[bx], 0x4420
0x9fbad: mov word ptr es:[bx + 0x460], 0x1120
0x9fbb4: mov word ptr es:[bx + 0x8c0], 0x6620
0x9fbbb: inc bx
0x9fbbc: inc bx
0x9fbbd: loop 0x9fba8
0x9fbbf: pop ds
0x9fbc0: pop es
2018-12-17T22:19:47.146828995Z 37 PC: 123d2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:47.147964619Z 42 PC: 9fb8c | Get date 0x9fb8c: cmp al, 5
0x9fb8e: jne 0x9fbbf
0x9fb90: mov ah, 9
0x9fb92: mov dx, 0x1ea
0x9fb95: push cs
0x9fb96: pop ds
0x9fb97: pushf
0x9fb98: lcall ptr cs:[0x1fd]
0x9fb9d: mov bx, 0xb800
0x9fba0: mov es, bx
0x9fba2: mov cx, 0x230
0x9fba5: mov bx, 0
0x9fba8: mov word ptr es:[bx], 0x4420
0x9fbad: mov word ptr es:[bx + 0x460], 0x1120
0x9fbb4: mov word ptr es:[bx + 0x8c0], 0x6620
0x9fbbb: inc bx
0x9fbbc: inc bx
0x9fbbd: loop 0x9fba8
0x9fbbf: pop ds
0x9fbc0: pop es
2018-12-17T22:19:47.150735551Z 62 PC: 122ab | Close file
2018-12-17T22:19:47.152410519Z 42 PC: 9fb8c | Get date 0x9fb8c: cmp al, 5
0x9fb8e: jne 0x9fbbf
0x9fb90: mov ah, 9
0x9fb92: mov dx, 0x1ea
0x9fb95: push cs
0x9fb96: pop ds
0x9fb97: pushf
0x9fb98: lcall ptr cs:[0x1fd]
0x9fb9d: mov bx, 0xb800
0x9fba0: mov es, bx
0x9fba2: mov cx, 0x230
0x9fba5: mov bx, 0
0x9fba8: mov word ptr es:[bx], 0x4420
0x9fbad: mov word ptr es:[bx + 0x460], 0x1120
0x9fbb4: mov word ptr es:[bx + 0x8c0], 0x6620
0x9fbbb: inc bx
0x9fbbc: inc bx
0x9fbbd: loop 0x9fba8
0x9fbbf: pop ds
0x9fbc0: pop es
2018-12-17T22:19:47.154599195Z 62 PC: 122ab | Close file
2018-12-17T22:19:47.156063524Z 42 PC: 9fb8c | Get date 0x9fb8c: cmp al, 5
0x9fb8e: jne 0x9fbbf
0x9fb90: mov ah, 9
0x9fb92: mov dx, 0x1ea
0x9fb95: push cs
0x9fb96: pop ds
0x9fb97: pushf
0x9fb98: lcall ptr cs:[0x1fd]
0x9fb9d: mov bx, 0xb800
0x9fba0: mov es, bx
0x9fba2: mov cx, 0x230
0x9fba5: mov bx, 0
0x9fba8: mov word ptr es:[bx], 0x4420
0x9fbad: mov word ptr es:[bx + 0x460], 0x1120
0x9fbb4: mov word ptr es:[bx + 0x8c0], 0x6620
0x9fbbb: inc bx
0x9fbbc: inc bx
0x9fbbd: loop 0x9fba8
0x9fbbf: pop ds
0x9fbc0: pop es
2018-12-17T22:19:47.159027061Z 62 PC: 122ab | Close file
2018-12-17T22:19:47.16068643Z 42 PC: 9fb8c | Get date 0x9fb8c: cmp al, 5
0x9fb8e: jne 0x9fbbf
0x9fb90: mov ah, 9
0x9fb92: mov dx, 0x1ea
0x9fb95: push cs
0x9fb96: pop ds
0x9fb97: pushf
0x9fb98: lcall ptr cs:[0x1fd]
0x9fb9d: mov bx, 0xb800
0x9fba0: mov es, bx
0x9fba2: mov cx, 0x230
0x9fba5: mov bx, 0
0x9fba8: mov word ptr es:[bx], 0x4420
0x9fbad: mov word ptr es:[bx + 0x460], 0x1120
0x9fbb4: mov word ptr es:[bx + 0x8c0], 0x6620
0x9fbbb: inc bx
0x9fbbc: inc bx
0x9fbbd: loop 0x9fba8
0x9fbbf: pop ds
0x9fbc0: pop es
2018-12-17T22:19:47.163063878Z 62 PC: 122ab | Close file
2018-12-17T22:19:47.165216282Z 42 PC: 9fb8c | Get date 0x9fb8c: cmp al, 5
0x9fb8e: jne 0x9fbbf
0x9fb90: mov ah, 9
0x9fb92: mov dx, 0x1ea
0x9fb95: push cs
0x9fb96: pop ds
0x9fb97: pushf
0x9fb98: lcall ptr cs:[0x1fd]
0x9fb9d: mov bx, 0xb800
0x9fba0: mov es, bx
0x9fba2: mov cx, 0x230
0x9fba5: mov bx, 0
0x9fba8: mov word ptr es:[bx], 0x4420
0x9fbad: mov word ptr es:[bx + 0x460], 0x1120
0x9fbb4: mov word ptr es:[bx + 0x8c0], 0x6620
0x9fbbb: inc bx
0x9fbbc: inc bx
0x9fbbd: loop 0x9fba8
0x9fbbf: pop ds
0x9fbc0: pop es
2018-12-17T22:19:47.167475437Z 62 PC: 122ab | Close file
2018-12-17T22:19:47.169013287Z 42 PC: 9fb8c | Get date 0x9fb8c: cmp al, 5
0x9fb8e: jne 0x9fbbf
0x9fb90: mov ah, 9
0x9fb92: mov dx, 0x1ea
0x9fb95: push cs
0x9fb96: pop ds
0x9fb97: pushf
0x9fb98: lcall ptr cs:[0x1fd]
0x9fb9d: mov bx, 0xb800
0x9fba0: mov es, bx
0x9fba2: mov cx, 0x230
0x9fba5: mov bx, 0
0x9fba8: mov word ptr es:[bx], 0x4420
0x9fbad: mov word ptr es:[bx + 0x460], 0x1120
0x9fbb4: mov word ptr es:[bx + 0x8c0], 0x6620
0x9fbbb: inc bx
0x9fbbc: inc bx
0x9fbbd: loop 0x9fba8
0x9fbbf: pop ds
0x9fbc0: pop es
2018-12-17T22:19:47.171835846Z 62 PC: 122ab | Close file
2018-12-17T22:19:47.173431122Z 42 PC: 9fb8c | Get date 0x9fb8c: cmp al, 5
0x9fb8e: jne 0x9fbbf
0x9fb90: mov ah, 9
0x9fb92: mov dx, 0x1ea
0x9fb95: push cs
0x9fb96: pop ds
0x9fb97: pushf
0x9fb98: lcall ptr cs:[0x1fd]
0x9fb9d: mov bx, 0xb800
0x9fba0: mov es, bx
0x9fba2: mov cx, 0x230
0x9fba5: mov bx, 0
0x9fba8: mov word ptr es:[bx], 0x4420
0x9fbad: mov word ptr es:[bx + 0x460], 0x1120
0x9fbb4: mov word ptr es:[bx + 0x8c0], 0x6620
0x9fbbb: inc bx
0x9fbbc: inc bx
0x9fbbd: loop 0x9fba8
0x9fbbf: pop ds
0x9fbc0: pop es
2018-12-17T22:19:47.17587815Z 62 PC: 122ab | Close file
2018-12-17T22:19:47.178596654Z 42 PC: 9fb8c | Get date 0x9fb8c: cmp al, 5
0x9fb8e: jne 0x9fbbf
0x9fb90: mov ah, 9
0x9fb92: mov dx, 0x1ea
0x9fb95: push cs
0x9fb96: pop ds
0x9fb97: pushf
0x9fb98: lcall ptr cs:[0x1fd]
0x9fb9d: mov bx, 0xb800
0x9fba0: mov es, bx
0x9fba2: mov cx, 0x230
0x9fba5: mov bx, 0
0x9fba8: mov word ptr es:[bx], 0x4420
0x9fbad: mov word ptr es:[bx + 0x460], 0x1120
0x9fbb4: mov word ptr es:[bx + 0x8c0], 0x6620
0x9fbbb: inc bx
0x9fbbc: inc bx
0x9fbbd: loop 0x9fba8
0x9fbbf: pop ds
0x9fbc0: pop es
2018-12-17T22:19:47.180976888Z 62 PC: 122ab | Close file
2018-12-17T22:19:47.183489922Z 42 PC: 9fb8c | Get date 0x9fb8c: cmp al, 5
0x9fb8e: jne 0x9fbbf
0x9fb90: mov ah, 9
0x9fb92: mov dx, 0x1ea
0x9fb95: push cs
0x9fb96: pop ds
0x9fb97: pushf
0x9fb98: lcall ptr cs:[0x1fd]
0x9fb9d: mov bx, 0xb800
0x9fba0: mov es, bx
0x9fba2: mov cx, 0x230
0x9fba5: mov bx, 0
0x9fba8: mov word ptr es:[bx], 0x4420
0x9fbad: mov word ptr es:[bx + 0x460], 0x1120
0x9fbb4: mov word ptr es:[bx + 0x8c0], 0x6620
0x9fbbb: inc bx
0x9fbbc: inc bx
0x9fbbd: loop 0x9fba8
0x9fbbf: pop ds
0x9fbc0: pop es
2018-12-17T22:19:47.189926624Z 62 PC: 122ab | Close file
2018-12-17T22:19:47.191612558Z 42 PC: 9fb8c | Get date 0x9fb8c: cmp al, 5
0x9fb8e: jne 0x9fbbf
0x9fb90: mov ah, 9
0x9fb92: mov dx, 0x1ea
0x9fb95: push cs
0x9fb96: pop ds
0x9fb97: pushf
0x9fb98: lcall ptr cs:[0x1fd]
0x9fb9d: mov bx, 0xb800
0x9fba0: mov es, bx
0x9fba2: mov cx, 0x230
0x9fba5: mov bx, 0
0x9fba8: mov word ptr es:[bx], 0x4420
0x9fbad: mov word ptr es:[bx + 0x460], 0x1120
0x9fbb4: mov word ptr es:[bx + 0x8c0], 0x6620
0x9fbbb: inc bx
0x9fbbc: inc bx
0x9fbbd: loop 0x9fba8
0x9fbbf: pop ds
0x9fbc0: pop es
2018-12-17T22:19:47.193823171Z 62 PC: 122ab | Close file
2018-12-17T22:19:47.196012327Z 42 PC: 9fb8c | Get date 0x9fb8c: cmp al, 5
0x9fb8e: jne 0x9fbbf
0x9fb90: mov ah, 9
0x9fb92: mov dx, 0x1ea
0x9fb95: push cs
0x9fb96: pop ds
0x9fb97: pushf
0x9fb98: lcall ptr cs:[0x1fd]
0x9fb9d: mov bx, 0xb800
0x9fba0: mov es, bx
0x9fba2: mov cx, 0x230
0x9fba5: mov bx, 0
0x9fba8: mov word ptr es:[bx], 0x4420
0x9fbad: mov word ptr es:[bx + 0x460], 0x1120
0x9fbb4: mov word ptr es:[bx + 0x8c0], 0x6620
0x9fbbb: inc bx
0x9fbbc: inc bx
0x9fbbd: loop 0x9fba8
0x9fbbf: pop ds
0x9fbc0: pop es
2018-12-17T22:19:47.198666323Z 62 PC: 122ab | Close file
2018-12-17T22:19:47.200506479Z 42 PC: 9fb8c | Get date 0x9fb8c: cmp al, 5
0x9fb8e: jne 0x9fbbf
0x9fb90: mov ah, 9
0x9fb92: mov dx, 0x1ea
0x9fb95: push cs
0x9fb96: pop ds
0x9fb97: pushf
0x9fb98: lcall ptr cs:[0x1fd]
0x9fb9d: mov bx, 0xb800
0x9fba0: mov es, bx
0x9fba2: mov cx, 0x230
0x9fba5: mov bx, 0
0x9fba8: mov word ptr es:[bx], 0x4420
0x9fbad: mov word ptr es:[bx + 0x460], 0x1120
0x9fbb4: mov word ptr es:[bx + 0x8c0], 0x6620
0x9fbbb: inc bx
0x9fbbc: inc bx
0x9fbbd: loop 0x9fba8
0x9fbbf: pop ds
0x9fbc0: pop es
2018-12-17T22:19:47.203215964Z 62 PC: 122ab | Close file
2018-12-17T22:19:47.205138268Z 42 PC: 9fb8c | Get date 0x9fb8c: cmp al, 5
0x9fb8e: jne 0x9fbbf
0x9fb90: mov ah, 9
0x9fb92: mov dx, 0x1ea
0x9fb95: push cs
0x9fb96: pop ds
0x9fb97: pushf
0x9fb98: lcall ptr cs:[0x1fd]
0x9fb9d: mov bx, 0xb800
0x9fba0: mov es, bx
0x9fba2: mov cx, 0x230
0x9fba5: mov bx, 0
0x9fba8: mov word ptr es:[bx], 0x4420
0x9fbad: mov word ptr es:[bx + 0x460], 0x1120
0x9fbb4: mov word ptr es:[bx + 0x8c0], 0x6620
0x9fbbb: inc bx
0x9fbbc: inc bx
0x9fbbd: loop 0x9fba8
0x9fbbf: pop ds
0x9fbc0: pop es
2018-12-17T22:19:47.207972025Z 62 PC: 122ab | Close file
2018-12-17T22:19:47.210193678Z 42 PC: 9fb8c | Get date 0x9fb8c: cmp al, 5
0x9fb8e: jne 0x9fbbf
0x9fb90: mov ah, 9
0x9fb92: mov dx, 0x1ea
0x9fb95: push cs
0x9fb96: pop ds
0x9fb97: pushf
0x9fb98: lcall ptr cs:[0x1fd]
0x9fb9d: mov bx, 0xb800
0x9fba0: mov es, bx
0x9fba2: mov cx, 0x230
0x9fba5: mov bx, 0
0x9fba8: mov word ptr es:[bx], 0x4420
0x9fbad: mov word ptr es:[bx + 0x460], 0x1120
0x9fbb4: mov word ptr es:[bx + 0x8c0], 0x6620
0x9fbbb: inc bx
0x9fbbc: inc bx
0x9fbbd: loop 0x9fba8
0x9fbbf: pop ds
0x9fbc0: pop es
2018-12-17T22:19:47.216708919Z 62 PC: 122ab | Close file
2018-12-17T22:19:47.218406388Z 42 PC: 9fb8c | Get date 0x9fb8c: cmp al, 5
0x9fb8e: jne 0x9fbbf
0x9fb90: mov ah, 9
0x9fb92: mov dx, 0x1ea
0x9fb95: push cs
0x9fb96: pop ds
0x9fb97: pushf
0x9fb98: lcall ptr cs:[0x1fd]
0x9fb9d: mov bx, 0xb800
0x9fba0: mov es, bx
0x9fba2: mov cx, 0x230
0x9fba5: mov bx, 0
0x9fba8: mov word ptr es:[bx], 0x4420
0x9fbad: mov word ptr es:[bx + 0x460], 0x1120
0x9fbb4: mov word ptr es:[bx + 0x8c0], 0x6620
0x9fbbb: inc bx
0x9fbbc: inc bx
0x9fbbd: loop 0x9fba8
0x9fbbf: pop ds
0x9fbc0: pop es
2018-12-17T22:19:47.220724616Z 62 PC: 122ab | Close file
2018-12-17T22:19:47.224818241Z 42 PC: 9fb8c | Get date 0x9fb8c: cmp al, 5
0x9fb8e: jne 0x9fbbf
0x9fb90: mov ah, 9
0x9fb92: mov dx, 0x1ea
0x9fb95: push cs
0x9fb96: pop ds
0x9fb97: pushf
0x9fb98: lcall ptr cs:[0x1fd]
0x9fb9d: mov bx, 0xb800
0x9fba0: mov es, bx
0x9fba2: mov cx, 0x230
0x9fba5: mov bx, 0
0x9fba8: mov word ptr es:[bx], 0x4420
0x9fbad: mov word ptr es:[bx + 0x460], 0x1120
0x9fbb4: mov word ptr es:[bx + 0x8c0], 0x6620
0x9fbbb: inc bx
0x9fbbc: inc bx
0x9fbbd: loop 0x9fba8
0x9fbbf: pop ds
0x9fbc0: pop es
2018-12-17T22:19:47.227374548Z 99 PC: 9a3b7 | Get DBCS lead byte table pointer
2018-12-17T22:19:47.229307263Z 42 PC: 9fb8c | Get date 0x9fb8c: cmp al, 5
0x9fb8e: jne 0x9fbbf
0x9fb90: mov ah, 9
0x9fb92: mov dx, 0x1ea
0x9fb95: push cs
0x9fb96: pop ds
0x9fb97: pushf
0x9fb98: lcall ptr cs:[0x1fd]
0x9fb9d: mov bx, 0xb800
0x9fba0: mov es, bx
0x9fba2: mov cx, 0x230
0x9fba5: mov bx, 0
0x9fba8: mov word ptr es:[bx], 0x4420
0x9fbad: mov word ptr es:[bx + 0x460], 0x1120
0x9fbb4: mov word ptr es:[bx + 0x8c0], 0x6620
0x9fbbb: inc bx
0x9fbbc: inc bx
0x9fbbd: loop 0x9fba8
0x9fbbf: pop ds
0x9fbc0: pop es
2018-12-17T22:19:47.235231968Z 56 PC: 94bd9 | Get or set country info
2018-12-17T22:19:47.236683052Z 42 PC: 9fb8c | Get date 0x9fb8c: cmp al, 5
0x9fb8e: jne 0x9fbbf
0x9fb90: mov ah, 9
0x9fb92: mov dx, 0x1ea
0x9fb95: push cs
0x9fb96: pop ds
0x9fb97: pushf
0x9fb98: lcall ptr cs:[0x1fd]
0x9fb9d: mov bx, 0xb800
0x9fba0: mov es, bx
0x9fba2: mov cx, 0x230
0x9fba5: mov bx, 0
0x9fba8: mov word ptr es:[bx], 0x4420
0x9fbad: mov word ptr es:[bx + 0x460], 0x1120
0x9fbb4: mov word ptr es:[bx + 0x8c0], 0x6620
0x9fbbb: inc bx
0x9fbbc: inc bx
0x9fbbd: loop 0x9fba8
0x9fbbf: pop ds
0x9fbc0: pop es
2018-12-17T22:19:47.238267234Z 64 PC: 9a628 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T22:19:47.241658347Z 42 PC: 9fb8c | Get date 0x9fb8c: cmp al, 5
0x9fb8e: jne 0x9fbbf
0x9fb90: mov ah, 9
0x9fb92: mov dx, 0x1ea
0x9fb95: push cs
0x9fb96: pop ds
0x9fb97: pushf
0x9fb98: lcall ptr cs:[0x1fd]
0x9fb9d: mov bx, 0xb800
0x9fba0: mov es, bx
0x9fba2: mov cx, 0x230
0x9fba5: mov bx, 0
0x9fba8: mov word ptr es:[bx], 0x4420
0x9fbad: mov word ptr es:[bx + 0x460], 0x1120
0x9fbb4: mov word ptr es:[bx + 0x8c0], 0x6620
0x9fbbb: inc bx
0x9fbbc: inc bx
0x9fbbd: loop 0x9fba8
0x9fbbf: pop ds
0x9fbc0: pop es
2018-12-17T22:19:47.243230821Z 25 PC: 94c42 | Get default drive
2018-12-17T22:19:47.244409201Z 42 PC: 9fb8c | Get date 0x9fb8c: cmp al, 5
0x9fb8e: jne 0x9fbbf
0x9fb90: mov ah, 9
0x9fb92: mov dx, 0x1ea
0x9fb95: push cs
0x9fb96: pop ds
0x9fb97: pushf
0x9fb98: lcall ptr cs:[0x1fd]
0x9fb9d: mov bx, 0xb800
0x9fba0: mov es, bx
0x9fba2: mov cx, 0x230
0x9fba5: mov bx, 0
0x9fba8: mov word ptr es:[bx], 0x4420
0x9fbad: mov word ptr es:[bx + 0x460], 0x1120
0x9fbb4: mov word ptr es:[bx + 0x8c0], 0x6620
0x9fbbb: inc bx
0x9fbbc: inc bx
0x9fbbd: loop 0x9fba8
0x9fbbf: pop ds
0x9fbc0: pop es
2018-12-17T22:19:47.246810327Z 71 PC: 96ebd | Get current directory
2018-12-17T22:19:47.251268681Z 42 PC: 9fb8c | Get date 0x9fb8c: cmp al, 5
0x9fb8e: jne 0x9fbbf
0x9fb90: mov ah, 9
0x9fb92: mov dx, 0x1ea
0x9fb95: push cs
0x9fb96: pop ds
0x9fb97: pushf
0x9fb98: lcall ptr cs:[0x1fd]
0x9fb9d: mov bx, 0xb800
0x9fba0: mov es, bx
0x9fba2: mov cx, 0x230
0x9fba5: mov bx, 0
0x9fba8: mov word ptr es:[bx], 0x4420
0x9fbad: mov word ptr es:[bx + 0x460], 0x1120
0x9fbb4: mov word ptr es:[bx + 0x8c0], 0x6620
0x9fbbb: inc bx
0x9fbbc: inc bx
0x9fbbd: loop 0x9fba8
0x9fbbf: pop ds
0x9fbc0: pop es
2018-12-17T22:19:47.25365053Z 64 PC: 9a628 | Write file or device (Write 3 bytes on handle 1)
2018-12-17T22:19:47.256437407Z 42 PC: 9fb8c | Get date 0x9fb8c: cmp al, 5
0x9fb8e: jne 0x9fbbf
0x9fb90: mov ah, 9
0x9fb92: mov dx, 0x1ea
0x9fb95: push cs
0x9fb96: pop ds
0x9fb97: pushf
0x9fb98: lcall ptr cs:[0x1fd]
0x9fb9d: mov bx, 0xb800
0x9fba0: mov es, bx
0x9fba2: mov cx, 0x230
0x9fba5: mov bx, 0
0x9fba8: mov word ptr es:[bx], 0x4420
0x9fbad: mov word ptr es:[bx + 0x460], 0x1120
0x9fbb4: mov word ptr es:[bx + 0x8c0], 0x6620
0x9fbbb: inc bx
0x9fbbc: inc bx
0x9fbbd: loop 0x9fba8
0x9fbbf: pop ds
0x9fbc0: pop es
2018-12-17T22:19:47.25910435Z 2 PC: 96e92 | Character output (Char = '3e')
2018-12-17T22:19:47.261476391Z 42 PC: 9fb8c | Get date 0x9fb8c: cmp al, 5
0x9fb8e: jne 0x9fbbf
0x9fb90: mov ah, 9
0x9fb92: mov dx, 0x1ea
0x9fb95: push cs
0x9fb96: pop ds
0x9fb97: pushf
0x9fb98: lcall ptr cs:[0x1fd]
0x9fb9d: mov bx, 0xb800
0x9fba0: mov es, bx
0x9fba2: mov cx, 0x230
0x9fba5: mov bx, 0
0x9fba8: mov word ptr es:[bx], 0x4420
0x9fbad: mov word ptr es:[bx + 0x460], 0x1120
0x9fbb4: mov word ptr es:[bx + 0x8c0], 0x6620
0x9fbbb: inc bx
0x9fbbc: inc bx
0x9fbbd: loop 0x9fba8
0x9fbbf: pop ds
0x9fbc0: pop es
2018-12-17T22:19:47.263769207Z 93 PC: 94d00 | File sharing functions
2018-12-17T22:19:47.265944581Z 42 PC: 9fb8c | Get date 0x9fb8c: cmp al, 5
0x9fb8e: jne 0x9fbbf
0x9fb90: mov ah, 9
0x9fb92: mov dx, 0x1ea
0x9fb95: push cs
0x9fb96: pop ds
0x9fb97: pushf
0x9fb98: lcall ptr cs:[0x1fd]
0x9fb9d: mov bx, 0xb800
0x9fba0: mov es, bx
0x9fba2: mov cx, 0x230
0x9fba5: mov bx, 0
0x9fba8: mov word ptr es:[bx], 0x4420
0x9fbad: mov word ptr es:[bx + 0x460], 0x1120
0x9fbb4: mov word ptr es:[bx + 0x8c0], 0x6620
0x9fbbb: inc bx
0x9fbbc: inc bx
0x9fbbd: loop 0x9fba8
0x9fbbf: pop ds
0x9fbc0: pop es
2018-12-17T22:19:47.268275369Z 93 PC: 94d07 | File sharing functions
2018-12-17T22:19:47.271029063Z 42 PC: 9fb8c | Get date 0x9fb8c: cmp al, 5
0x9fb8e: jne 0x9fbbf
0x9fb90: mov ah, 9
0x9fb92: mov dx, 0x1ea
0x9fb95: push cs
0x9fb96: pop ds
0x9fb97: pushf
0x9fb98: lcall ptr cs:[0x1fd]
0x9fb9d: mov bx, 0xb800
0x9fba0: mov es, bx
0x9fba2: mov cx, 0x230
0x9fba5: mov bx, 0
0x9fba8: mov word ptr es:[bx], 0x4420
0x9fbad: mov word ptr es:[bx + 0x460], 0x1120
0x9fbb4: mov word ptr es:[bx + 0x8c0], 0x6620
0x9fbbb: inc bx
0x9fbbc: inc bx
0x9fbbd: loop 0x9fba8
0x9fbbf: pop ds
0x9fbc0: pop es
2018-12-17T22:19:47.273903817Z 10 PC: 94d19 | Buffered keyboard input

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":3416,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:49:02.450925151Z 65 PC: 12a52 | Delete file (Filename = 'is started by using +the SHELL command in the CONFIG.SYS file. F##¸#ã#,$z$À$%U% %à%,&y&')
2018-12-25T11:49:02.45755263Z 42 PC: 9fb8c | Get date 0x9fb8c: cmp al, 5
0x9fb8e: jne 0x9fbbf
0x9fb90: mov ah, 9
0x9fb92: mov dx, 0x1ea
0x9fb95: push cs
0x9fb96: pop ds
0x9fb97: pushf
0x9fb98: lcall ptr cs:[0x1fd]
0x9fb9d: mov bx, 0xb800
0x9fba0: mov es, bx
0x9fba2: mov cx, 0x230
0x9fba5: mov bx, 0
0x9fba8: mov word ptr es:[bx], 0x4420
0x9fbad: mov word ptr es:[bx + 0x460], 0x1120
0x9fbb4: mov word ptr es:[bx + 0x8c0], 0x6620
0x9fbbb: inc bx
0x9fbbc: inc bx
0x9fbbd: loop 0x9fba8
0x9fbbf: pop ds
0x9fbc0: pop es
2018-12-25T11:49:02.459740002Z 77 PC: 11fe0 | Get program return code
2018-12-25T11:49:02.461140537Z 42 PC: 9fb8c | Get date (See above)
2018-12-25T11:49:02.464253985Z 72 PC: 12174 | Allocate memory
2018-12-25T11:49:02.466548883Z 42 PC: 9fb8c | Get date (See above)
2018-12-25T11:49:02.468821701Z 72 PC: 1218d | Allocate memory
2018-12-25T11:49:02.471152433Z 42 PC: 9fb8c | Get date (See above)
2018-12-25T11:49:02.475860496Z 37 PC: 123c4 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-25T11:49:02.476974385Z 42 PC: 9fb8c | Get date (See above)
2018-12-25T11:49:02.479010396Z 37 PC: 123cb | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-25T11:49:02.481148383Z 42 PC: 9fb8c | Get date (See above)
2018-12-25T11:49:02.483779672Z 37 PC: 123d2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T11:49:02.485400962Z 42 PC: 9fb8c | Get date (See above)
2018-12-25T11:49:02.489072464Z 62 PC: 122ab | Close file
2018-12-25T11:49:02.491080589Z 42 PC: 9fb8c | Get date (See above)
2018-12-25T11:49:02.493601487Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:49:02.496629546Z 42 PC: 9fb8c | Get date (See above)
2018-12-25T11:49:02.499269415Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:49:02.501080774Z 42 PC: 9fb8c | Get date (See above)
2018-12-25T11:49:02.503540333Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:49:02.505953209Z 42 PC: 9fb8c | Get date (See above)
2018-12-25T11:49:02.508118398Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:49:02.509648797Z 42 PC: 9fb8c | Get date (See above)
2018-12-25T11:49:02.524150865Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:49:02.526029659Z 42 PC: 9fb8c | Get date (See above)
2018-12-25T11:49:02.528343792Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:49:02.531047494Z 42 PC: 9fb8c | Get date (See above)
2018-12-25T11:49:02.533394806Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:49:02.53510224Z 42 PC: 9fb8c | Get date (See above)
2018-12-25T11:49:02.538576747Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:49:02.540402723Z 42 PC: 9fb8c | Get date (See above)
2018-12-25T11:49:02.542503461Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:49:02.545108691Z 42 PC: 9fb8c | Get date (See above)
2018-12-25T11:49:02.54804554Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:49:02.550339989Z 42 PC: 9fb8c | Get date (See above)
2018-12-25T11:49:02.553694843Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:49:02.556207641Z 42 PC: 9fb8c | Get date (See above)
2018-12-25T11:49:02.559147815Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:49:02.561634279Z 42 PC: 9fb8c | Get date (See above)
2018-12-25T11:49:02.563794424Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:49:02.565253372Z 42 PC: 9fb8c | Get date (See above)
2018-12-25T11:49:02.567507781Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:49:02.571060247Z 42 PC: 9fb8c | Get date (See above)
2018-12-25T11:49:02.573157312Z 99 PC: 9a3b7 | Get DBCS lead byte table pointer
2018-12-25T11:49:02.574509895Z 42 PC: 9fb8c | Get date (See above)
2018-12-25T11:49:02.576940879Z 56 PC: 94bd9 | Get or set country info
2018-12-25T11:49:02.578855553Z 42 PC: 9fb8c | Get date (See above)
2018-12-25T11:49:02.580889235Z 64 PC: 9a628 | Write file or device (Write 2 bytes on handle 1)
2018-12-25T11:49:02.585347171Z 42 PC: 9fb8c | Get date (See above)
2018-12-25T11:49:02.587303134Z 25 PC: 94c42 | Get default drive
2018-12-25T11:49:02.588681012Z 42 PC: 9fb8c | Get date (See above)
2018-12-25T11:49:02.591379284Z 71 PC: 96ebd | Get current directory
2018-12-25T11:49:02.595032985Z 42 PC: 9fb8c | Get date (See above)
2018-12-25T11:49:02.597323798Z 64 PC: 9a628 | Write file or device (See above)
2018-12-25T11:49:02.6012888Z 42 PC: 9fb8c | Get date (See above)
2018-12-25T11:49:02.603784727Z 2 PC: 96e92 | Character output (Char = '3e')
2018-12-25T11:49:02.606312291Z 42 PC: 9fb8c | Get date (See above)
2018-12-25T11:49:02.610078207Z 93 PC: 94d00 | File sharing functions
2018-12-25T11:49:02.611991084Z 42 PC: 9fb8c | Get date (See above)
2018-12-25T11:49:02.614329818Z 93 PC: 94d07 | File sharing functions
2018-12-25T11:49:02.616770841Z 42 PC: 9fb8c | Get date (See above)
2018-12-25T11:49:02.619009566Z 10 PC: 94d19 | Buffered keyboard input

{"DateBased":true,"Day":4,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":3416,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:49:06.353557047Z 65 PC: 12a52 | Delete file (Filename = 'is started by using +the SHELL command in the CONFIG.SYS file. F##¸#ã#,$z$À$%U% %à%,&y&')
2018-12-25T11:49:06.359871349Z 42 PC: 9fb8c | Get date 0x9fb8c: cmp al, 5
0x9fb8e: jne 0x9fbbf
0x9fb90: mov ah, 9
0x9fb92: mov dx, 0x1ea
0x9fb95: push cs
0x9fb96: pop ds
0x9fb97: pushf
0x9fb98: lcall ptr cs:[0x1fd]
0x9fb9d: mov bx, 0xb800
0x9fba0: mov es, bx
0x9fba2: mov cx, 0x230
0x9fba5: mov bx, 0
0x9fba8: mov word ptr es:[bx], 0x4420
0x9fbad: mov word ptr es:[bx + 0x460], 0x1120
0x9fbb4: mov word ptr es:[bx + 0x8c0], 0x6620
0x9fbbb: inc bx
0x9fbbc: inc bx
0x9fbbd: loop 0x9fba8
0x9fbbf: pop ds
0x9fbc0: pop es
2018-12-25T11:49:06.362726051Z 9 PC: 9fb9d | Display string (Could not find end pointer)
2018-12-25T11:49:06.368131652Z 77 PC: 11fe0 | Get program return code
2018-12-25T11:49:06.370590306Z 42 PC: 9fb8c | Get date (See above)
2018-12-25T11:49:06.373601602Z 9 PC: 9fb9d | Display string (See above)
2018-12-25T11:49:06.378094402Z 72 PC: 12174 | Allocate memory
2018-12-25T11:49:06.380025537Z 42 PC: 9fb8c | Get date (See above)
2018-12-25T11:49:06.382604346Z 9 PC: 9fb9d | Display string (See above)
2018-12-25T11:49:06.388296373Z 72 PC: 1218d | Allocate memory
2018-12-25T11:49:06.390620736Z 42 PC: 9fb8c | Get date (See above)
2018-12-25T11:49:06.393149963Z 9 PC: 9fb9d | Display string (See above)
2018-12-25T11:49:06.397689113Z 37 PC: 123c4 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-25T11:49:06.399380616Z 42 PC: 9fb8c | Get date (See above)
2018-12-25T11:49:06.412760537Z 9 PC: 9fb9d | Display string (See above)
2018-12-25T11:49:06.417147783Z 37 PC: 123cb | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-25T11:49:06.418240923Z 42 PC: 9fb8c | Get date (See above)
2018-12-25T11:49:06.420786326Z 9 PC: 9fb9d | Display string (See above)
2018-12-25T11:49:06.42548626Z 37 PC: 123d2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T11:49:06.427054709Z 42 PC: 9fb8c | Get date (See above)
2018-12-25T11:49:06.43252403Z 9 PC: 9fb9d | Display string (See above)
2018-12-25T11:49:06.437068759Z 62 PC: 122ab | Close file
2018-12-25T11:49:06.438736356Z 42 PC: 9fb8c | Get date (See above)
2018-12-25T11:49:06.444672725Z 9 PC: 9fb9d | Display string (See above)
2018-12-25T11:49:06.450987535Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:49:06.452468444Z 42 PC: 9fb8c | Get date (See above)
2018-12-25T11:49:06.455162911Z 9 PC: 9fb9d | Display string (See above)
2018-12-25T11:49:06.459841141Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:49:06.461277348Z 42 PC: 9fb8c | Get date (See above)
2018-12-25T11:49:06.463957738Z 9 PC: 9fb9d | Display string (See above)
2018-12-25T11:49:06.468921618Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:49:06.470567472Z 42 PC: 9fb8c | Get date (See above)
2018-12-25T11:49:06.473596712Z 9 PC: 9fb9d | Display string (See above)
2018-12-25T11:49:06.478629788Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:49:06.480452182Z 42 PC: 9fb8c | Get date (See above)
2018-12-25T11:49:06.483376307Z 9 PC: 9fb9d | Display string (See above)
2018-12-25T11:49:06.499277261Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:49:06.501094827Z 42 PC: 9fb8c | Get date (See above)
2018-12-25T11:49:06.504188944Z 9 PC: 9fb9d | Display string (See above)
2018-12-25T11:49:06.508539286Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:49:06.509972434Z 42 PC: 9fb8c | Get date (See above)
2018-12-25T11:49:06.513194382Z 9 PC: 9fb9d | Display string (See above)
2018-12-25T11:49:06.517519024Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:49:06.520185004Z 42 PC: 9fb8c | Get date (See above)
2018-12-25T11:49:06.52288075Z 9 PC: 9fb9d | Display string (See above)
2018-12-25T11:49:06.527511282Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:49:06.529277783Z 42 PC: 9fb8c | Get date (See above)
2018-12-25T11:49:06.532574969Z 9 PC: 9fb9d | Display string (See above)
2018-12-25T11:49:06.536897137Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:49:06.538375025Z 42 PC: 9fb8c | Get date (See above)
2018-12-25T11:49:06.540637892Z 9 PC: 9fb9d | Display string (See above)
2018-12-25T11:49:06.547064426Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:49:06.548580573Z 42 PC: 9fb8c | Get date (See above)
2018-12-25T11:49:06.550627325Z 9 PC: 9fb9d | Display string (See above)
2018-12-25T11:49:06.555063111Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:49:06.556441319Z 42 PC: 9fb8c | Get date (See above)
2018-12-25T11:49:06.558397146Z 9 PC: 9fb9d | Display string (See above)
2018-12-25T11:49:06.563215774Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:49:06.564636168Z 42 PC: 9fb8c | Get date (See above)
2018-12-25T11:49:06.566669404Z 9 PC: 9fb9d | Display string (See above)
2018-12-25T11:49:06.572309478Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:49:06.573712151Z 42 PC: 9fb8c | Get date (See above)
2018-12-25T11:49:06.575721006Z 9 PC: 9fb9d | Display string (See above)
2018-12-25T11:49:06.5818434Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:49:06.584678844Z 42 PC: 9fb8c | Get date (See above)
2018-12-25T11:49:06.586701981Z 9 PC: 9fb9d | Display string (See above)
2018-12-25T11:49:06.592139904Z 99 PC: 9a3b7 | Get DBCS lead byte table pointer
2018-12-25T11:49:06.594101464Z 42 PC: 9fb8c | Get date (See above)
2018-12-25T11:49:06.596125653Z 9 PC: 9fb9d | Display string (See above)
2018-12-25T11:49:06.601247954Z 56 PC: 94bd9 | Get or set country info
2018-12-25T11:49:06.603079169Z 42 PC: 9fb8c | Get date (See above)
2018-12-25T11:49:06.605077354Z 9 PC: 9fb9d | Display string (See above)
2018-12-25T11:49:06.610525406Z 64 PC: 9a628 | Write file or device (Write 2 bytes on handle 1)
2018-12-25T11:49:06.614809929Z 42 PC: 9fb8c | Get date (See above)
2018-12-25T11:49:06.616725926Z 9 PC: 9fb9d | Display string (See above)
2018-12-25T11:49:06.621332005Z 25 PC: 94c42 | Get default drive
2018-12-25T11:49:06.623012018Z 42 PC: 9fb8c | Get date (See above)
2018-12-25T11:49:06.625244089Z 9 PC: 9fb9d | Display string (See above)
2018-12-25T11:49:06.632058903Z 71 PC: 96ebd | Get current directory
2018-12-25T11:49:06.636046117Z 42 PC: 9fb8c | Get date (See above)
2018-12-25T11:49:06.638267964Z 9 PC: 9fb9d | Display string (See above)
2018-12-25T11:49:06.643177349Z 64 PC: 9a628 | Write file or device (See above)
2018-12-25T11:49:06.647212996Z 42 PC: 9fb8c | Get date (See above)
2018-12-25T11:49:06.649572943Z 9 PC: 9fb9d | Display string (See above)
2018-12-25T11:49:06.654939093Z 2 PC: 96e92 | Character output (Char = '3e')
2018-12-25T11:49:06.657260427Z 42 PC: 9fb8c | Get date (See above)
2018-12-25T11:49:06.659385392Z 9 PC: 9fb9d | Display string (See above)
2018-12-25T11:49:06.664590527Z 93 PC: 94d00 | File sharing functions
2018-12-25T11:49:06.666794822Z 42 PC: 9fb8c | Get date (See above)
2018-12-25T11:49:06.66909188Z 9 PC: 9fb9d | Display string (See above)
2018-12-25T11:49:06.674953146Z 93 PC: 94d07 | File sharing functions
2018-12-25T11:49:06.677321362Z 42 PC: 9fb8c | Get date (See above)
2018-12-25T11:49:06.68000667Z 9 PC: 9fb9d | Display string (See above)
2018-12-25T11:49:06.684486526Z 10 PC: 94d19 | Buffered keyboard input